A small federal agency best known for recalling faulty appliances and children’s products is now pressing hospitals to hand over detailed, personally identifiable emergency room records on a scale that has privacy lawyers and hospital counsel on edge.
The Consumer Product Safety Commission wants at least 100 hospitals to begin transmitting full patient data—names, addresses, diagnoses, and other sensitive details—from emergency visits by the end of the year. The information would flow to a private contractor, Konza Health, for analysis. Documents and correspondence reviewed by journalists show the agency and its contractor describing participation as mandatory or required, a sharp break from the long-standing voluntary system that relied almost exclusively on de-identified data.
From Product Injuries to Nearly Everything
For decades the CPSC has operated the National Electronic Injury Surveillance System, or NEISS. Participating hospitals reported injuries linked to consumer products, typically stripped of identifiers. The data helped the agency spot patterns and issue recalls.
The new approach is far broader. According to internal materials and emails, Konza would pull records covering more than 10,000 diagnostic codes. The list includes injuries with no connection to products the CPSC regulates—vaccine reactions, contact with stingrays, adult suicide attempts, and a wide range of other emergency presentations. The contractor’s agreements reviewed so far contain no clear limits matching the agency’s own historical operating manual, which instructed hospitals to exclude names, birthdates, and addresses except in the rare cases requiring follow-up investigation.
Acting leadership has framed the change as modernization, citing artificial intelligence and the need for larger data volumes. Konza has stated it will remove identifiers before sending information onward to the CPSC and is prohibited by contract from selling or marketing the data. Privacy experts remain unconvinced that routing millions of identifiable records through a private intermediary is low-risk.
Legal Authority and Process Questions
Federal law generally requires notice and a public comment period before an agency requests information from ten or more entities. That step appears not to have occurred. Hospital systems across the country report being approached directly, with some told they must seek an exemption if they decline.
CPSC officials have pointed to information-blocking rules as a potential enforcement lever. Hospital attorneys counter that sharing identifiable patient data without a clear legal mandate could itself create liability under federal privacy law. Several large systems have declined or are still evaluating participation, citing patient privacy as the primary concern.
The episode arrives amid broader federal efforts to expand access to medical records, including requests from other agencies and private organizations working with Health and Human Services. It also coincides with significant turnover at the CPSC itself, including the removal of its previous Democratic commissioners and the departure of a substantial share of career staff.
Privacy Risks Are Not Theoretical
The CPSC has experienced data incidents before. Between 2017 and 2019 the agency improperly released personal health information belonging to roughly 30,000 people. Expanding the volume and sensitivity of data collected multiplies the potential harm from any future breach or misuse.
Handing identifiable records to a private contractor introduces additional vectors: cybersecurity risk, secondary use pressures, and the simple reality that more parties with access means more opportunities for error or overreach. Even if the contractor strips identifiers before transmission, the initial collection of full patient files creates a larger attack surface and a longer retention window than the old de-identified model.
Compliance and Operational Realities for Hospitals
For hospital compliance teams, the situation creates an uncomfortable conflict between competing federal expectations. On one side sits the threat of information-blocking penalties if they refuse to share. On the other sits the risk of HIPAA violations or state privacy law exposure if they transmit identifiable data without a solid legal basis. Many systems that previously participated in the voluntary NEISS program are now reassessing whether the new terms remain defensible.
The absence of on-site hospital staff trained specifically for product-injury coding also raises quality concerns. Automated extraction of thousands of diagnostic codes may generate volume, but it risks diluting the very product-safety insights the agency claims to need. Former agency leadership has publicly questioned whether the push prioritizes quantity of records over thoughtful collection of relevant data.
Patients, meanwhile, have almost no practical visibility into whether their emergency visit will be swept into the system, how long the data will be held, or what secondary uses might emerge once a private contractor holds the files. In an environment already strained by high-profile breaches and expanding government data requests, that opacity further erodes trust.
What Hospitals and Patients Should Watch
Some hospitals that previously participated in NEISS have already signed new agreements; others are pushing back or seeking clarity. The absence of a formal rulemaking process leaves the legal foundation uncertain. Patients whose records may be swept into the system have limited visibility into how the data will be used, how long it will be retained, or what safeguards truly apply.
The core tension is familiar to anyone working in privacy and compliance: the desire for richer data to improve public safety colliding with the obligation to minimize identifiable information and respect established legal limits. Expanding surveillance of emergency room visits without clear statutory authority, proper process, or robust public accountability does not resolve that tension—it intensifies it.
Whether the program proceeds as currently framed, faces legal challenge, or is narrowed remains to be seen. What is already clear is that the shift from limited, de-identified product-injury reporting to broad collection of identifiable medical records represents a material change in both scope and risk. Hospitals, privacy officers, and policymakers will need to watch closely how this experiment unfolds and whether adequate guardrails are put in place before millions of sensitive records begin moving.